Skip to main content

Android Car Head Units Infected by MoYu Proxy Botnet Malware

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Android car head units are infected, forming a proxy botnet and engaging in ad fraud for the MoYu Group.
  • Affected systems include DoFun Android-based car head units managed by the TWCore system app.
  • Users should check for and apply firmware updates from DoFun or their car manufacturer.

Advertisement

Supply Chain Attack Targets Android Car Head Units with MoYu Malware

Kaspersky researchers have uncovered a novel supply-chain attack leveraging a legitimate device-update application to distribute malware, enrolling compromised Android car head units into a proxy botnet or using them for advertising fraud. This operation has been attributed to the MoYu group, a threat actor previously associated with the BadBox malware botnet. This marks the first documented instance of a malware infection chain specifically engineered for the targeted car head unit ecosystem, highlighting an evolving threat landscape in connected vehicles.

The attack primarily targets systems provided by DoFun, a Chinese automotive software and hardware vendor. DoFun supplies generic Android-based head units that serve as command centers for vehicle infotainment, navigation, and settings. While the malware does not interfere with driving or critical vehicle control systems, its presence underscores a significant breach of trust within the automotive supply chain and presents new avenues for attacker monetization, according to BleepingComputer.

Technical Analysis: DoFun TWCore Supply Chain Compromise

The infection chain begins with a rogue APK file downloaded through a legitimate DoFun system app named TWCore. TWCore receives instructions from an MQTT server hosted at cardoor[.]cn. This unidentified application, devoid of any user interface, is a piece of malware dubbed ‘JarService’. Upon execution, JarService decrypts and launches a second-stage loader. This loader then establishes communication with a command-and-control (C2) server to download an additional encrypted payload.

The final payload functions as the core operational component of the botnet. It periodically reports comprehensive device information, including model, display resolution, Wi-Fi SSID, and MAC address, while also retrieving commands from the attackers. The malware supports nine distinct commands, allowing the MoYu group significant control over the compromised devices. Researchers observed that the primary module loaded was ‘zhima,’ a reverse-proxy module that transforms the infected head unit into a node within a proxy botnet. Furthermore, the malware was noted making web requests consistent with click-fraud activities, indicating its dual purpose for monetization.

This sophisticated approach to compromising a supply chain component like the TWCore app to deploy multi-stage malware demonstrates a targeted and calculated effort by the MoYu group to establish a foothold in a nascent attack vector. Security professionals investigating how to detect MoYu Group malware on Android head units should focus on unusual network traffic patterns originating from these devices, particularly connections to unknown C2 infrastructure or ad-fraud related domains.

Actionable Recommendations for Mitigation

While the immediate impact of this specific malware does not extend to critical vehicle safety, the compromise of a legitimate software update channel for car head units raises serious concerns about the integrity of the automotive supply chain. Defenders must prioritize proactive measures for mitigation for car infotainment botnets to prevent similar or more severe future attacks.

Prioritized Actions:

  • Firmware Updates: The most crucial step for affected individuals is to check for and promptly apply any available firmware updates or patches from DoFun or their specific car manufacturer. Kaspersky states they notified DoFun, and the company indicated the problem was resolved, suggesting a patch may be available.
  • Network Monitoring: For organizations managing fleets or with sufficient technical capabilities, monitor network traffic originating from car head units. Look for suspicious connections to unusual IP addresses or domains, especially those related to proxy services or known malicious C2 infrastructure.
  • Supply Chain Vigilance: Automotive OEMs and software providers must enhance their supply chain security protocols. This includes rigorous vetting of third-party software, regular security audits of update mechanisms, and implementing strong code signing practices to prevent unauthorized modifications to legitimate applications like TWCore.
  • User Awareness: While difficult for end-users to detect this type of sophisticated supply chain attack, general best practices around purchasing devices from trusted sources and being wary of unofficial updates remain relevant.

Related: Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service, npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises

Advertisement

Advertisement